Back to skill

Security audit

akshare-stock-analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed stock charting and analysis helper that fetches public market data and writes local chart/report files, with no evidence of hidden persistence, credential access, exfiltration, or destructive behavior.

Install only if you are comfortable with the skill contacting AkShare for public market and financial data and saving chart/report files locally. Treat its analysis as informational, verify outputs independently before making investment decisions, and expect reliable operation primarily for A-share symbols despite HK/US examples in the documentation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad stock-analysis skill that takes a symbol/name, detects market, fetches data, plots multiple indicators including ATR, and produces rich analytical output. The supplied code chunk is much narrower: it is a chart-rendering utility that expects preloaded daily OHLCV data with indicators already present and saves a static PNG using matplotlib. Its four panels are price/candles with MA and Bollinger bands, volume, MACD, and RSI only. Although the smoke-test imports a fetch function, the primary implemented behavior in this chunk is chart rendering, not end-to-end market detection, data retrieval, multi-timeframe analysis, or structured narrative analysis. Therefore the description materially overstates and misrepresents the behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk's purpose is narrowly focused on event annotation: it queries ak.news_economic_baidu(), filters events by date and importance, falls back to a hardcoded China macro calendar, and adds earnings-season warnings. While 'event-aware risk notes' are mentioned in the declared description, this file only implements that supporting sub-feature and none of the main advertised stock-analysis functionality. Because the declared purpose emphasizes comprehensive stock charting and analysis, but the actual code performs only macro event retrieval unrelated to stock symbol processing or technical analysis, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a full stock analysis skill with market detection, visualization, multiple indicator calculations, multi-timeframe confirmation, and narrative/structured insights. This code chunk is much narrower: it is a data-fetching utility for A-share OHLCV history only. It retrieves daily, weekly, and monthly bars and normalizes columns, but contains no market auto-detection, no charting, no indicator computation, and no analysis/reporting features. While weekly/monthly retrieval could support later multi-timeframe analysis, this chunk by itself does not implement the described end-user behavior, so the description materially overstates what the supplied code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description covers an end-to-end stock analysis skill, including symbol/market detection, data retrieval, visualization, and rich interpretive outputs. The supplied code chunk is a narrow indicator-calculation module. It adds MA, Bollinger Bands, MACD, RSI, ATR, and support/resistance to a DataFrame, and adds MA20/RSI to weekly/monthly frames. While this partially supports the declared technical-indicator and multi-timeframe aspects, it does not implement most of the claimed end-user functionality. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a broad technical-analysis and reporting skill centered on price-series retrieval, charting, multiple technical indicators, timeframe confirmation, and narrative investment analysis. The supplied code chunk instead implements only a valuation helper module for A-share symbols. It retrieves earnings/financial statement summary data and historical financial ratios via AkShare, and optionally computes PE and PB from a provided last close. This is not merely a partial implementation detail of the declared skill; its primary purpose is materially narrower and different. While 'valuation context' is one small element mentioned in the description, the code lacks the core advertised capabilities and is specifically scoped to A-share financial data rather than the full market-detection and technical analysis workflow.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documentation advertises executable scripts that generate reports and save chart files, but it declares no explicit tool scope or permissions boundary. In an agent environment, missing scope declarations can let the runtime grant broader file-write capability than the user expects, increasing the chance of unintended writes or abuse if downstream scripts are modified or invoked with attacker-controlled paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown specifies a fixed language default of 'Bilingual: Chinese label + English explanation,' which imposes a locale/language behavior on users rather than offering a choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified or optional.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The top-level documentation states the script is for a given 'A-share symbol', implying a narrower supported scope. In code, fetch_all_timeframes and fetch_timeframe accept any code string and pass it directly to ak.stock_zh_a_hist without checking that it is actually an A-share symbol, so the documented intent is more specific than the implementation enforces.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.